Scaled Score
A score adjusted for question difficulty, not a raw percentage.
Getting Started: SC-100 Exam Essentials
Free knowledge base
Everything from the course in one searchable place: 378 entries. Use it to review before a practice test or look up a word you forgot.
378 results · showing first 300, refine your search
A score adjusted for question difficulty, not a raw percentage.
Getting Started: SC-100 Exam Essentials
A major domain or section of the exam objectives.
Getting Started: SC-100 Exam Essentials
The percentage of the exam dedicated to a specific objective area.
Getting Started: SC-100 Exam Essentials
A detailed scenario requiring multiple-choice or solution-building answers.
Getting Started: SC-100 Exam Essentials
The official document listing all exam objectives and sub-objectives.
Getting Started: SC-100 Exam Essentials
A security model based on the principle 'never trust, always verify'.
Getting Started: SC-100 Exam Essentials
Governance, Risk, and Compliance – frameworks for managing organizational policies.
Getting Started: SC-100 Exam Essentials
To remember the exam's focus: 'I P D S' - Identity, Platforms, Data, Security Operations. Think 'I Protect Data Securely!'
Getting Started: SC-100 Exam Essentials
The SC-100 exam is an Expert-level certification. It requires a foundational certification (like SC-200, SC-300, or AZ-500) as a prerequisite, or demonstrable equivalent experience. This is a crucial detail for exam eligibility.
Getting Started: SC-100 Exam Essentials
Underestimating the importance of case studies and scenario-based questions, which often require synthesizing knowledge from multiple domains.
Getting Started: SC-100 Exam Essentials
Failing to consult the official Microsoft Learn skills outline for the most current exam objectives and weightings, leading to studying outdated or irrelevant topics.
Getting Started: SC-100 Exam Essentials
Focusing solely on memorization rather than understanding the architectural principles and how to apply them in diverse, real-world scenarios.
Getting Started: SC-100 Exam Essentials
Free online training platform by Microsoft with learning paths and modules.
Getting Started: SC-100 Exam Essentials
Curated collection of modules designed to teach a specific skill or prepare for an exam.
Getting Started: SC-100 Exam Essentials
A self-contained unit within a learning path, covering a specific topic.
Getting Started: SC-100 Exam Essentials
Temporary, free Azure subscription for hands-on practice within Microsoft Learn.
Getting Started: SC-100 Exam Essentials
Official technical documentation platform for Microsoft products and services.
Getting Started: SC-100 Exam Essentials
Resource for information on Microsoft's security, privacy, and compliance practices.
Getting Started: SC-100 Exam Essentials
Official document outlining the specific topics and abilities assessed on an exam.
Getting Started: SC-100 Exam Essentials
Learn Docs Trust! Learn for training, Docs for details, Trust for compliance. L-D-T, like a reliable car!
Getting Started: SC-100 Exam Essentials
The exam expects you to know *where* to find information, not just the information itself. Keywords like 'official documentation', 'Microsoft Learn', 'Trust Center', and 'Skills Measured' are critical. Memorize the purpose of each key resource.
Getting Started: SC-100 Exam Essentials
Relying solely on third-party study guides without cross-referencing official Microsoft documentation.
Getting Started: SC-100 Exam Essentials
Skipping the hands-on exercises in Microsoft Learn sandboxes, missing crucial practical experience.
Getting Started: SC-100 Exam Essentials
Not reviewing the 'Skills Measured' document, leading to studying irrelevant topics or missing key ones.
Getting Started: SC-100 Exam Essentials
Automatic trust based on network location.
Zero Trust Strategy Fundamentals
Granting minimum necessary access rights.
Zero Trust Strategy Fundamentals
Ongoing re-evaluation of access requests.
Zero Trust Strategy Fundamentals
Access based on user, device, location, risk.
Zero Trust Strategy Fundamentals
Identity as the primary security boundary.
Zero Trust Strategy Fundamentals
Design security as if a breach will occur.
Zero Trust Strategy Fundamentals
Granular network segmentation for isolation.
Zero Trust Strategy Fundamentals
I Eat Apples Daily In New York (Identities, Endpoints, Applications, Data, Infrastructure, Network)
Zero Trust Strategy Fundamentals
The exam frequently tests your understanding of the 'never trust, always verify' mantra and the six pillars. Be ready to identify which pillar applies to a given scenario. Remember that 'Identity' is often considered the new control plane or perimeter.
Zero Trust Strategy Fundamentals
Thinking Zero Trust is a product you can buy, rather than a strategy and philosophy.
Zero Trust Strategy Fundamentals
Believing Zero Trust only applies to external users or cloud resources, ignoring internal traffic.
Zero Trust Strategy Fundamentals
Confusing Zero Trust with simply implementing Multi-Factor Authentication (MFA); MFA is a component, not the whole strategy.
Zero Trust Strategy Fundamentals
System managing digital identities and authentication.
Zero Trust Strategy Fundamentals
Requires two or more verification factors.
Zero Trust Strategy Fundamentals
Secures and monitors accounts with elevated permissions.
Zero Trust Strategy Fundamentals
Grants temporary, time-bound elevated permissions.
Zero Trust Strategy Fundamentals
Manages identity lifecycle and access rights.
Zero Trust Strategy Fundamentals
I.D.E.N.T.I.T.Y. - **I**dentity Provider, **D**ynamic Policies, **E**levated Access (PAM), **N**o Implicit Trust, **T**hreat Detection, **I**ntegrated Controls, **T**wo-Factor (MFA), **Y**es to Verification.
Zero Trust Strategy Fundamentals
Memorize the core components of Microsoft Entra ID (formerly Azure AD) that support Zero Trust identity: Conditional Access, Identity Protection, Privileged Identity Management (PIM), and MFA. The exam often tests your ability to map scenarios to these specific Microsoft technologies.
Zero Trust Strategy Fundamentals
Relying solely on passwords without MFA, which is easily compromised.
Zero Trust Strategy Fundamentals
Not implementing Just-In-Time (JIT) access for privileged accounts, leaving them constantly exposed.
Zero Trust Strategy Fundamentals
Failing to integrate identity signals with broader security monitoring for comprehensive threat detection.
Zero Trust Strategy Fundamentals
Tools that monitor and respond to cyber threats on endpoints.
Zero Trust Strategy Fundamentals
Manages and protects corporate data within applications on personal devices.
Zero Trust Strategy Fundamentals
Manages and secures entire mobile devices, often corporate-owned.
Zero Trust Strategy Fundamentals
Securely publishes on-premises web applications to external users.
Zero Trust Strategy Fundamentals
Security policy enforcement points between cloud users and cloud apps.
Zero Trust Strategy Fundamentals
Cloud-based service for mobile device and application management.
Zero Trust Strategy Fundamentals
Enterprise endpoint security platform for prevention, detection, investigation, and response.
Zero Trust Strategy Fundamentals
E.N.D.P.O.I.N.T.S. – Every Network Device Protects Our Information, Never Trust, Secure! This reminds you that all endpoints are critical control points.
Zero Trust Strategy Fundamentals
The exam frequently tests your understanding of how Microsoft technologies like Intune (MDM/MAM), Defender for Endpoint (EDR), and Entra ID (Conditional Access, Application Proxy) specifically contribute to Zero Trust for endpoints and applications. Memorize their core functions.
Zero Trust Strategy Fundamentals
Treating internal network endpoints as inherently trustworthy.
Zero Trust Strategy Fundamentals
Failing to apply Zero Trust principles to unmanaged personal devices (BYOD).
Zero Trust Strategy Fundamentals
Neglecting continuous monitoring and automated response for endpoint and application security events.
Zero Trust Strategy Fundamentals
Categorizing data by sensitivity to apply appropriate security.
Zero Trust Strategy Fundamentals
Microsoft's solution for data classification, labeling, and encryption.
Zero Trust Strategy Fundamentals
Tools to prevent sensitive data from leaving controlled environments.
Zero Trust Strategy Fundamentals
Granting minimum necessary permissions for a task.
Zero Trust Strategy Fundamentals
Cloud security posture management and threat protection.
Zero Trust Strategy Fundamentals
Manages, controls, and monitors access to important resources.
Zero Trust Strategy Fundamentals
To protect your 'D.A.T.A.' with Zero Trust: 'D' for Data Classification, 'A' for Access Controls, 'T' for Transit/Rest Encryption, 'A' for Always Verify.
Zero Trust Strategy Fundamentals
The SC-100 exam frequently tests your understanding of how specific Microsoft technologies map to Zero Trust principles for data and infrastructure. Memorize the core function of Purview Information Protection (classification, labeling, encryption) and Defender for Cloud (posture management, threat protection) as they relate to these pillars.
Zero Trust Strategy Fundamentals
Assuming internal network traffic is inherently safe without verification.
Zero Trust Strategy Fundamentals
Failing to classify data, leading to inconsistent protection policies.
Zero Trust Strategy Fundamentals
Over-provisioning administrative access instead of using JIT/JEA.
Zero Trust Strategy Fundamentals
Access policies that adapt in real-time based on current risk signals.
Zero Trust Strategy Fundamentals
Security rules that adjust access decisions based on calculated risk.
Zero Trust Strategy Fundamentals
Data collected from systems to monitor performance and security.
Zero Trust Strategy Fundamentals
To remember Continuous Verification and Least Privilege, think: 'C.V.L.P. - Constantly Verify, Limit Privileges.' Like a bouncer at a club who checks ID repeatedly and only lets you into the specific areas you paid for.
Zero Trust Strategy Fundamentals
The exam often tests scenarios where access decisions change based on conditions. Look for keywords like 'conditional access,' 'dynamic policy,' 'real-time,' 'risk score,' or 'just-in-time' as indicators of continuous verification and least privilege in action.
Zero Trust Strategy Fundamentals
Assuming initial authentication is sufficient for ongoing trust.
Zero Trust Strategy Fundamentals
Granting standing administrative privileges instead of JIT/JEA.
Zero Trust Strategy Fundamentals
Failing to regularly review and revoke unnecessary permissions.
Zero Trust Strategy Fundamentals
To remember the Zero Trust pillars: I EAT DINNER. Identity, Endpoints, Applications, Data, Infrastructure, Network.
Zero Trust Architecture & Hybrid/Multi-Cloud
The SC-100 exam emphasizes that Zero Trust is a strategic approach, not a single product. Focus on the 'never trust, always verify' principle and the pillars: Identity, Endpoints, Applications, Data, Infrastructure, and Network.
Zero Trust Architecture & Hybrid/Multi-Cloud
Assuming Zero Trust is a product you can buy off the shelf.
Zero Trust Architecture & Hybrid/Multi-Cloud
Neglecting continuous monitoring after initial access is granted.
Zero Trust Architecture & Hybrid/Multi-Cloud
Focusing only on network perimeter and ignoring identity and device trust.
Zero Trust Architecture & Hybrid/Multi-Cloud
Centralizes security logs for analysis and threat detection.
Zero Trust Architecture & Hybrid/Multi-Cloud
Protects web applications from common web-based attacks.
Zero Trust Architecture & Hybrid/Multi-Cloud
To remember key integrations: 'I'M N.E.T. D.A.S.H.' - Identity, Micro-segmentation, Network, Endpoint, Threat intelligence, Data, Application, SIEM, Health checks.
Zero Trust Architecture & Hybrid/Multi-Cloud
The SC-100 exam emphasizes how Microsoft's security services (e.g., Entra ID Conditional Access, Defender for Endpoint, Sentinel) integrate to achieve Zero Trust. Focus on how these existing controls are enhanced, not replaced, and how they feed into a centralized policy engine.
Zero Trust Architecture & Hybrid/Multi-Cloud
Trying to replace all existing security controls at once instead of integrating them incrementally.
Zero Trust Architecture & Hybrid/Multi-Cloud
Neglecting to update or strengthen existing controls (like MFA) before attempting Zero Trust integration.
Zero Trust Architecture & Hybrid/Multi-Cloud
Failing to establish continuous monitoring and feedback loops from existing controls into the Zero Trust policy engine.
Zero Trust Architecture & Hybrid/Multi-Cloud
Combines on-premises infrastructure with public cloud services.
Zero Trust Architecture & Hybrid/Multi-Cloud
Isolating workloads to limit lateral movement within a network.
Zero Trust Architecture & Hybrid/Multi-Cloud
Managing and automating security policies through code.
Zero Trust Architecture & Hybrid/Multi-Cloud
Single source of truth for user and group identities.
Zero Trust Architecture & Hybrid/Multi-Cloud
Data subject to legal frameworks of the country it resides in.
Zero Trust Architecture & Hybrid/Multi-Cloud
Technique attackers use to move deeper into a network.
Zero Trust Architecture & Hybrid/Multi-Cloud
H-Y-B-R-I-D: **H**ardening, **Y**ielding to no trust, **B**oundaries everywhere, **R**eal-time verification, **I**dentity-centric, **D**ata protection.
Zero Trust Architecture & Hybrid/Multi-Cloud
The exam often tests your understanding of how Zero Trust principles like 'verify explicitly' and 'assume breach' apply across on-premises and cloud boundaries. Look for questions about consistent policy enforcement and unified identity management.
Zero Trust Architecture & Hybrid/Multi-Cloud
Treating on-premises and cloud security as entirely separate domains, leading to policy inconsistencies.
Zero Trust Architecture & Hybrid/Multi-Cloud
Failing to establish a unified identity management system across hybrid environments.
Zero Trust Architecture & Hybrid/Multi-Cloud
Neglecting microsegmentation for on-premises workloads, focusing only on cloud-native segmentation.
Zero Trust Architecture & Hybrid/Multi-Cloud
Using two or more public cloud providers for IT infrastructure.
Zero Trust Architecture & Hybrid/Multi-Cloud
Linking identity systems to allow single sign-on across platforms.
Zero Trust Architecture & Hybrid/Multi-Cloud
Cloud Security Posture Management; identifies cloud misconfigurations.
Zero Trust Architecture & Hybrid/Multi-Cloud
Cloud Workload Protection Platform; secures workloads across clouds.
Zero Trust Architecture & Hybrid/Multi-Cloud
Infrastructure as Code; managing infrastructure through code.
Zero Trust Architecture & Hybrid/Multi-Cloud
A single interface for managing security across multiple clouds.
Zero Trust Architecture & Hybrid/Multi-Cloud
Think 'UCI-MAPS' for Multi-Cloud Zero Trust: Unified Identity, Consistent Policies, Micro-segmentation, Automation, Protection (CSPM/CWPP), SIEM/SOAR.
Zero Trust Architecture & Hybrid/Multi-Cloud
The exam emphasizes that Microsoft Entra ID (formerly Azure AD) is Microsoft's primary solution for unified identity in multi-cloud scenarios. Remember its capabilities for federation and Conditional Access.
Zero Trust Architecture & Hybrid/Multi-Cloud
Assuming cloud-native security tools from one provider will automatically integrate perfectly with another.
Zero Trust Architecture & Hybrid/Multi-Cloud
Neglecting to centralize identity management, leading to fragmented access policies and increased attack surface.
Zero Trust Architecture & Hybrid/Multi-Cloud
Failing to implement consistent monitoring and logging across all cloud environments, creating blind spots.
Zero Trust Architecture & Hybrid/Multi-Cloud
Structured approach for governance, risk, and compliance management.
GRC Technical Strategies
Voluntary framework for managing cybersecurity risk.
GRC Technical Strategies
International standard for Information Security Management Systems.
GRC Technical Strategies
Standard for organizations handling credit card data.
GRC Technical Strategies
US law protecting sensitive patient health information.
GRC Technical Strategies
Report on security, availability, processing integrity, etc.
GRC Technical Strategies
Suite of unified data governance solutions.
GRC Technical Strategies
Tool to manage compliance posture within Microsoft Purview.
GRC Technical Strategies
NIST, ISO, PCI, HIPAA, SOC — Never Ignore Security Protocols, It's Highly Important, So Obey Compliance!
GRC Technical Strategies
The exam often tests your ability to match specific regulations or industry types with the most appropriate GRC framework. Keywords to look for include 'healthcare data' (HIPAA), 'credit card processing' (PCI DSS), or 'general information security' (ISO 27001, NIST CSF). Remember that Microsoft Purview Compliance Manager is a key tool for managing compliance within Microsoft environments.
GRC Technical Strategies
Choosing a GRC framework based solely on popularity without considering specific organizational needs or regulatory obligations.
GRC Technical Strategies
Failing to map GRC requirements to specific technical controls and configurations within the Microsoft ecosystem.
GRC Technical Strategies
Treating GRC as a one-time project rather than a continuous process of monitoring and improvement.
GRC Technical Strategies
A control designed to stop an incident before it occurs.
GRC Technical Strategies
A control designed to identify an incident after it has occurred.
GRC Technical Strategies
A control designed to restore systems after an incident.
GRC Technical Strategies
Assigns permissions based on a user's job function.
GRC Technical Strategies
Encrypting data when it is stored on a device or in a database.
GRC Technical Strategies
Aggregates and analyzes security logs for real-time alerts.
GRC Technical Strategies
To remember the control types: P.D.C. - Prevent, Detect, Correct. Think of a 'Police Department Car' – it tries to Prevent crime, Detects if one happens, and Corrects the situation.
GRC Technical Strategies
The exam often presents scenarios where you need to choose the most appropriate technical control to address a specific GRC requirement or risk. Pay close attention to keywords like 'prevent unauthorized access,' 'detect anomalies,' or 'ensure data integrity' to guide your choice. Memorize the primary function of common controls like firewalls, IPS, EDR, and SIEM.
GRC Technical Strategies
Confusing administrative controls (policies) with technical controls (software/hardware implementations).
GRC Technical Strategies
Selecting a detective control when a preventive control is primarily needed for a specific risk.
GRC Technical Strategies
Overlooking the importance of continuous monitoring and logging as a technical control for GRC.
GRC Technical Strategies
Policies and processes for managing data assets.
GRC Technical Strategies
Protection of personal data from unauthorized access/use.
GRC Technical Strategies
EU regulation for data protection and privacy.
GRC Technical Strategies
California laws protecting consumer personal information.
GRC Technical Strategies
Policies defining how long data must be kept.
GRC Technical Strategies
Transforms data to prevent unauthorized access.
GRC Technical Strategies
To remember the Data Governance lifecycle: I C P M R A (Identify, Classify, Protect, Monitor, Retain, Audit). Imagine a 'C'lassified 'P'olice 'M'an 'R'etaining 'A'll the data!
GRC Technical Strategies
The exam often tests your knowledge of specific regulations like GDPR and CCPA. Be prepared to identify which regulation applies to a given scenario and what rights it grants to data subjects or consumers. Focus on the core principles and key requirements of each.
GRC Technical Strategies
Confusing data governance with data privacy; they are related but distinct concepts.
GRC Technical Strategies
Failing to consider the global impact of data privacy regulations (e.g., GDPR's extraterritorial scope).
GRC Technical Strategies
Implementing technical controls without a clear data classification scheme, leading to ineffective protection.
GRC Technical Strategies
Process of identifying, assessing, and controlling threats to an organization.
GRC Technical Strategies
Proactive approach to identify potential threats and vulnerabilities in systems.
GRC Technical Strategies
Uses descriptive terms (low, medium, high) for likelihood and impact.
GRC Technical Strategies
Assigns numerical values, often monetary, to risk likelihood and impact.
GRC Technical Strategies
Threat modeling methodology for Spoofing, Tampering, Repudiation, Info Disclosure, DoS, EoP.
GRC Technical Strategies
Risk-centric, seven-step threat modeling methodology.
GRC Technical Strategies
The amount of risk an organization is willing to accept.
GRC Technical Strategies
To remember STRIDE, think of a 'STRIDE' to security: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege.
GRC Technical Strategies
The exam often tests your understanding of the different threat modeling methodologies and their applications. Be prepared to distinguish between STRIDE, PASTA, and DREAD, and know when to apply qualitative versus quantitative risk assessment. Look for keywords like 'design phase' for threat modeling, or 'monetary impact' for quantitative risk.
GRC Technical Strategies
Confusing threat modeling (proactive, design-focused) with vulnerability scanning (reactive, post-deployment).
GRC Technical Strategies
Applying only qualitative assessment when financial impact is critical and quantifiable data is available.
GRC Technical Strategies
Failing to integrate threat modeling outputs into the broader risk management framework.
GRC Technical Strategies
Security Operations Center; centralized function for security monitoring and response.
Security Operations Strategies
Managed Security Service Provider; external vendor providing outsourced security services.
Security Operations Strategies
Endpoint Detection and Response; monitors and responds to threats on endpoints.
Security Operations Strategies
Security Orchestration, Automation, and Response; automates security tasks.
Security Operations Strategies
Structured approach to handling and managing security breaches.
Security Operations Strategies
Information about current and potential threats and adversaries.
Security Operations Strategies
SOC: People, Processes, Tech. Remember PPT for a successful SOC!
Security Operations Strategies
The exam expects you to differentiate between SOC models (in-house, outsourced, hybrid) and understand the core functions and technology components (SIEM, EDR, SOAR) essential for a modern SOC. Look for questions about strategic alignment and continuous improvement.
Security Operations Strategies
Underestimating the ongoing operational costs and staffing requirements for an in-house SOC.
Security Operations Strategies
Failing to integrate the SOC strategy with the broader business and risk management objectives.
Security Operations Strategies
Investing in advanced security tools without having the skilled personnel or defined processes to effectively use them.
Security Operations Strategies
Documented procedures for handling security incidents.
Security Operations Strategies
Restoring IT systems/data after a disruptive event.
Security Operations Strategies
Maintaining critical business functions during disruptions.
Security Operations Strategies
Average time from incident detection to resolution.
Security Operations Strategies
Discussion-based simulation to test incident response plans.
Security Operations Strategies
Step-by-step guide for responding to specific incident types.
Security Operations Strategies
Review after an incident to identify lessons learned.
Security Operations Strategies
P-I-C-E-R-P: Prepare, Identify, Contain, Eradicate, Recover, Post-incident. (Like a spicy 'P-I-C-E-R' pie!)
Security Operations Strategies
The SC-100 exam expects you to differentiate between incident response, disaster recovery, and business continuity. Focus on the scope and objectives of each. Remember the NIST Incident Response lifecycle phases.
Security Operations Strategies
Confusing Disaster Recovery (IT focus) with Business Continuity (broader business focus).
Security Operations Strategies
Failing to regularly test plans, leading to outdated or ineffective procedures.
Security Operations Strategies
Skipping the 'lessons learned' phase, preventing continuous improvement.
Security Operations Strategies
High-level insights into adversary motivations and capabilities.
Security Operations Strategies
Details on adversary TTPs (Tactics, Techniques, Procedures).
Security Operations Strategies
Specific IOCs (Indicators of Compromise) for immediate defense.
Security Operations Strategies
Proactive search for undetected threats in a network.
Security Operations Strategies
Indicators of Compromise; evidence of a security breach.
Security Operations Strategies
Tactics, Techniques, and Procedures; adversary behaviors.
Security Operations Strategies
Remember the types of intelligence with 'STOP': Strategic, Tactical, Operational. STOP bad guys!
Security Operations Strategies
The exam often tests your understanding of the different types of threat intelligence and their appropriate use cases. Be prepared to distinguish between strategic (executive, long-term), tactical (security teams, TTPs), and operational (SOC, IOCs) intelligence. Keywords like 'adversary motivation' point to strategic, 'attack vectors' to tactical, and 'IP addresses' to operational.
Security Operations Strategies
Treating all threat intelligence as equally urgent or relevant without proper context or filtering.
Security Operations Strategies
Confusing threat hunting with traditional alert-driven incident response; hunting is proactive, IR is reactive.
Security Operations Strategies
Failing to integrate threat hunting findings back into security controls and processes, breaking the feedback loop.
Security Operations Strategies
Network Detection and Response; analyzes network traffic for anomalies.
Security Operations Strategies
User and Entity Behavior Analytics; detects anomalous user activities.
Security Operations Strategies
An alert indicating a threat when no real threat exists.
Security Operations Strategies
Indicator of Compromise; forensic data indicating a breach.
Security Operations Strategies
To remember key monitoring data sources, think 'LEAF': Logs, Endpoints, Applications, Flows.
Security Operations Strategies
The SC-100 exam frequently tests your understanding of integrating Microsoft security services for monitoring. Be prepared to identify which Azure service (e.g., Azure Sentinel, Defender for Cloud, Azure Monitor) is best suited for specific monitoring or alerting scenarios.
Security Operations Strategies
Over-alerting: Generating too many low-fidelity alerts, leading to alert fatigue and missed critical incidents.
Security Operations Strategies
Under-monitoring: Not collecting data from critical systems or blind spots, leaving vulnerabilities undetected.
Security Operations Strategies
Lack of context: Alerts lacking sufficient detail for analysts to quickly understand the threat and decide on next steps.
Security Operations Strategies
Temporarily opens management ports to VMs on demand.
Infrastructure Security Design
Encrypts OS and data disks for Azure VMs using BitLocker or DM-Crypt.
Infrastructure Security Design
A managed, private Docker registry service in Azure.
Infrastructure Security Design
A managed Kubernetes service for deploying and managing containerized applications.
Infrastructure Security Design
Azure AD identities for Azure resources, eliminating credential management.
Infrastructure Security Design
Filters network traffic to and from Azure resources in a virtual network.
Infrastructure Security Design
V-C-S-A-M: VMs, Containers, Security Center, Access, Monitoring. Remember these five pillars for compute security!
Infrastructure Security Design
The SC-100 exam frequently tests knowledge of specific Azure services for compute security. Memorize the primary function of Microsoft Defender for Cloud (CSPM/CWP), Azure Key Vault (secrets management), and Azure AD (IAM) in the context of VMs and containers. Look for keywords like 'vulnerability management,' 'disk encryption,' or 'container image scanning.'
Infrastructure Security Design
Forgetting to encrypt both OS and data disks for VMs, leaving sensitive data vulnerable.
Infrastructure Security Design
Running containers with root privileges or using untrusted base images, creating significant security holes.
Infrastructure Security Design
Failing to implement JIT VM access, leaving RDP/SSH ports open to the internet unnecessarily.
Infrastructure Security Design
Isolated private network in Azure for resources.
Infrastructure Security Design
Logical division of a VNET for segmentation.
Infrastructure Security Design
Managed, stateful network firewall service.
Infrastructure Security Design
Protects web applications from common attacks.
Infrastructure Security Design
Network topology for centralized security.
Infrastructure Security Design
Dividing networks to limit breach impact.
Infrastructure Security Design
VNETs are like your house, Subnets are the rooms, NSGs are the room doors, Azure Firewall is the main entrance gate, and WAF is the security guard for your web-facing windows.
Infrastructure Security Design
On the exam, pay close attention to the differences between NSGs, Azure Firewall, and Azure WAF. NSGs are for basic Layer 4 filtering, Azure Firewall is for stateful network-level protection (Layer 3-7 with Premium), and Azure WAF is for Layer 7 web application protection. Keywords like 'web application attacks' point to WAF, 'centralized network security' to Azure Firewall, and 'basic traffic filtering for VMs' to NSGs.
Infrastructure Security Design
Confusing NSGs with Azure Firewall: NSGs are stateless and basic; Azure Firewall is stateful and advanced.
Infrastructure Security Design
Not applying NSGs at both subnet and NIC levels: While subnet NSGs are common, NIC-level NSGs can provide more granular control.
Infrastructure Security Design
Forgetting to consider default NSG rules: Default rules allow some traffic, which might unintentionally expose resources if not overridden or supplemented.
Infrastructure Security Design
Default encryption for data at rest in Azure Storage, using AES-256.
Infrastructure Security Design
Encryption keys stored in Azure Key Vault, managed by the customer.
Infrastructure Security Design
Delegated access with limited permissions and time for storage resources.
Infrastructure Security Design
Extends VNet private address space to Azure services over optimized route.
Infrastructure Security Design
Provides private connectivity to Azure services over a private endpoint.
Infrastructure Security Design
Allows recovery of accidentally deleted blobs or containers for a period.
Infrastructure Security Design
Stores data in a WORM state, non-erasable and non-modifiable.
Infrastructure Security Design
Encrypt All Storage Safely: E (Encryption), A (Access Control), S (Shared Access Signatures), S (Soft Delete).
Infrastructure Security Design
On the SC-100 exam, pay close attention to scenarios involving compliance, data residency, and key management. Understand when to recommend Microsoft-managed keys versus customer-managed keys (CMK) and the implications for control and responsibility. Keywords like 'regulatory compliance,' 'data sovereignty,' or 'customer control over encryption keys' often point to CMK.
Infrastructure Security Design
Relying solely on Microsoft-managed encryption keys when compliance requires customer control.
Infrastructure Security Design
Using storage account access keys directly in applications instead of SAS or RBAC.
Infrastructure Security Design
Not configuring network restrictions (firewalls, VNet integration) for sensitive storage accounts.
Infrastructure Security Design
Managing infrastructure using code, not manual processes.
Infrastructure Security Design
Unauthorized or unintended changes to infrastructure configuration.
Infrastructure Security Design
Analyzing code for vulnerabilities without executing it.
Infrastructure Security Design
Securely storing and managing sensitive information like keys.
Infrastructure Security Design
Automated process for building, testing, and deploying software.
Infrastructure Security Design
Identifying when deployed infrastructure deviates from its definition.
Infrastructure Security Design
Integrating security practices early in the development lifecycle.
Infrastructure Security Design
IaC: 'I Always Code' for 'Infrastructure as Code'. Remember to 'Secure All Code' (SAST) and 'Keep Vaults Locked' (Key Vaults)!
Infrastructure Security Design
The SC-100 exam often tests on the principles of 'shift-left' security and the importance of integrating security into CI/CD pipelines for IaC. Memorize that Azure Policy is a key tool for enforcing compliance and detecting configuration drift in Azure environments.
Infrastructure Security Design
Hardcoding sensitive credentials directly into IaC templates.
Infrastructure Security Design
Not performing security scans on IaC templates before deployment.
Infrastructure Security Design
Granting overly permissive permissions to IaC deployment identities or service principals.
Infrastructure Security Design
Applying metadata tags to data assets indicating classification.
Data Security Design
Microsoft Purview labels enforcing classification-based protection.
Data Security Design
Personally Identifiable Information, used to identify an individual.
Data Security Design
Protected Health Information, health data covered by HIPAA.
Data Security Design
Data Loss Prevention, systems preventing unauthorized data exfiltration.
Data Security Design
C.L.A.S.S.I.F.Y.: Categorize, Label, Apply, Secure, Standardize, Integrate, Follow-up, Yield results.
Data Security Design
On the SC-100 exam, you must be able to recommend appropriate data classification schemes and protection strategies. Keywords to look for include 'sensitivity,' 'regulatory compliance,' and 'information protection policies.' Understand the capabilities of Microsoft Purview Information Protection (MPIP) and its role in implementing labels.
Data Security Design
Creating overly complex classification schemes that are difficult for users to understand and apply consistently.
Data Security Design
Failing to involve business stakeholders in defining classification categories, leading to impractical or misaligned policies.
Data Security Design
Implementing classification without corresponding automated protection, relying solely on user judgment for security.
Data Security Design
Patterns or definitions used to identify specific types of sensitive data.
Data Security Design
Rules defining what sensitive data to protect, where, and what actions to take.
Data Security Design
Real-time notification to users about potential policy violations.
Data Security Design
Response taken when a DLP policy is triggered (e.g., block, notify).
Data Security Design
Microsoft's comprehensive DLP solution integrated across M365 services.
Data Security Design
DLP policy mode that monitors violations without enforcing actions.
Data Security Design
DLP: Don't Let PII (Personally Identifiable Information) or IP (Intellectual Property) leave! Remember the 'P' for Prevention.
Data Security Design
The exam often tests your understanding of the different locations where DLP policies can apply (Exchange, SharePoint, OneDrive, Teams, Endpoints, Cloud Apps) and the various enforcement actions available (block, notify, encrypt, quarantine). Look for scenarios that require choosing the most appropriate action.
Data Security Design
Implementing overly restrictive DLP policies from the start, leading to excessive false positives and user frustration.
Data Security Design
Failing to regularly review and update DLP policies as business needs and data types evolve.
Data Security Design
Not utilizing audit-only mode to test policies before full enforcement, potentially disrupting legitimate business operations.
Data Security Design
Uses a single, shared secret key for both encryption and decryption.
Data Security Design
Uses a public/private key pair; public for encrypt, private for decrypt.
Data Security Design
Physical device safeguarding and managing cryptographic keys.
Data Security Design
Regularly replacing active encryption keys with new ones.
Data Security Design
Invalidating a compromised or no longer needed key.
Data Security Design
Data stored on persistent storage, like databases or backups.
Data Security Design
Data actively moving across networks.
Data Security Design
Encrypts entire databases without application changes.
Data Security Design
KISS: Keep It Secret, Securely Stored. Remember the 'secret' part for the private key in asymmetric encryption and 'securely stored' for HSMs.
Data Security Design
The exam frequently tests your understanding of Azure Key Vault's role in key management, including its integration with other Azure services and its FIPS 140-2 compliance. Be prepared to differentiate between software-protected keys and HSM-protected keys.
Data Security Design
Using weak or easily guessable encryption keys.
Data Security Design
Not having a robust key rotation policy, leaving old keys active indefinitely.
Data Security Design
Storing encryption keys directly alongside the encrypted data without additional protection.
Data Security Design
Failing to revoke compromised keys promptly.
Data Security Design
Protocols providing secure, encrypted communication over a computer network.
Data Security Design
Creates a secure, encrypted connection over a less secure network like the internet.
Data Security Design
Encrypts an entire storage device, protecting all data stored on it.
Data Security Design
Mechanisms that determine who or what can access a resource.
Data Security Design
A layered security approach using multiple security controls.
Data Security Design
To remember the two states: 'R'est is 'R'oom (storage), 'T'ransit is 'T'ravel (movement).
Data Security Design
The SC-100 exam frequently tests your ability to choose the correct security control based on the data's state. Look for keywords like 'transferring data,' 'network communication,' or 'uploading' for in-transit, and 'stored on disk,' 'database,' or 'backup' for at-rest. Remember that encryption is a primary control for both states, but the specific technologies differ.
Data Security Design
Assuming one type of encryption (e.g., VPN) protects all data states; it primarily protects data in transit, not necessarily at rest.
Data Security Design
Neglecting physical security for data at rest, especially for on-premises solutions or backup media.
Data Security Design
Implementing encryption without a robust key management strategy, which can negate the security benefits.
Data Security Design
A process integrating security into all phases of software development.
Application Security Design
Integrating security activities earlier in the development process.
Application Security Design
Integrating security practices into DevOps for continuous security.
Application Security Design
Analyzes source code for vulnerabilities without executing it.
Application Security Design
Tests running applications for vulnerabilities by simulating attacks.
Application Security Design
Identifies open-source components and their known vulnerabilities.
Application Security Design
Automated checkpoints in CI/CD to enforce security policies.
Application Security Design
SDL: Secure Design, Logic, Development. Remember to 'Shift Left' for security!
Application Security Design